We invite you to read the final report of our third security audit, concluded in mid-June 2023, with many fixes deployed late June 2023. Further re-tests and a verification pass was performed during July.

  • Radically Open Security found no information leakage or logging of customer data
  • RoS discovered 1 High, 6 Elevated, 4 Moderate, 10 Low and 4 info-severity issues during this penetration test.
you are viewing a single comment's thread
view the rest of the comments
[–] 38 points 3 years ago (2 children)

Forgot one point

  • got in trouble for not offering port forwarding anymore
  • source
  • hideshow 4 child comments
  • [–] 10 points 3 years ago (1 child)

    Yeah I had to move to another provider over this. It's sad, I like their policies and services, but it's a deal breaker.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 3 years ago (2 children)

    why do you need to port forward over vpn?

  • source
  • parent
  • hideshow 4 child comments
  • [–] 1 point 3 years ago

    I've used it to open a local port on my laptop publicly without needing to make any changes to the local network I was on. It can be useful for opening your laptop's ssh port or to host an http server to send someone a big file you don't want to pay to upload somewhere.

    One other common use is 🏴‍☠️ which I suspect is why they disabled the service :/

  • source
  • parent
  • [–] 4 points 3 years ago (1 child)

    Getting in trouble? It's more like:

    • Server providers threatening to terminate business with Mullvad because some of its users used port forwarding to host contents that meant legal trouble.
    • Mullvad chose to terminate support for port forwarding in a transparent way and gave clear dates to prepare. This was done instead of selling off their users or collaborating with whatever legal threats they were facing.

    I don't like it, but at least I understand their business decision. Even if I took my business elsewhere, they have a solid point on transparency.

  • source
  • parent
  • hideshow 2 child comments